Executive brief
A type confusion vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks and state management across multiple Apple operating systems and the Safari browser.
Affected products
- Apple WebKit
- Apple Safari before 16.3
- Apple iOS before 15.7.4, 16.0 to before 16.3.1
- Apple iPadOS before 15.7.4, 16.0 to before 16.3.1
- Apple macOS Ventura 13.0 to before 13.2.1
Timeline
- 2023-02-14: disclosed
- 2023-02-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-14: patched: Fixed in iOS/iPadOS 16.3.1, macOS 13.2.1, and Safari 16.3
- 2023-02-14: exploited: Apple reported awareness of active exploitation at time of release.